SchemaPin Verification
Verify the cryptographic integrity of MCP tool schemas to ensure they haven't been tampered with.
Verification Process
- Identify the MCP server to verify (from the extension manifest or the user's request)
- Use the
symbi__verify_schematool to check the schema - Report the verification result:
- Verified: Schema signature matches the publisher's key
- TOFU: First-time use, key has been pinned for future verification
- Failed: Schema has been modified since signing -- DO NOT USE
- No signature: Schema is unsigned -- warn the user about risks
When to Verify
- Before first use of any new MCP tool
- After updating MCP server configurations
- When security audit is requested
- When a tool returns unexpected results
Note on Tool Names
In Gemini CLI, MCP tools are prefixed with the server alias and double underscore.
The symbi MCP tools are accessed as symbi__verify_schema, symbi__list_agents, etc.